logo

CVE-2022-45395 com.thalesgroup.jenkins-ci.plugins:cccc

Package

Manager: maven
Name: com.thalesgroup.jenkins-ci.plugins:cccc
Vulnerable Version: >=0 <=0.6

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00296 pctl0.52474

Details

XML External Entity Reference in Jenkins CCCC Plugin Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Metadata

Created: 2022-11-16T12:00:23Z
Modified: 2025-04-30T20:27:29Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-f3gj-hvv4-f57v/GHSA-f3gj-hvv4-f57v.json
CWE IDs: ["CWE-611"]
Alternative ID: GHSA-f3gj-hvv4-f57v
Finding: F083
Auto approve: 1